
October 19, 2025 - Daily Cybersecurity News
Malicious Google Ads Distribute Infostealers via Fake Homebrew and LogMeIn Sites
HighWhat happened
Threat actors are leveraging malicious Google advertisements to direct users to counterfeit websites mimicking Homebrew, LogMeIn, and TradingView. These sites prompt users to execute commands in the Terminal, leading to the installation of infostealing malware such as AMOS (Atomic macOS Stealer) and Odyssey.
Who is affected
macOS developers and users seeking to download or update software from Homebrew, LogMeIn, and TradingView platforms are the primary targets of this campaign.
Why it matters
The distribution of infostealing malware through trusted platforms poses significant risks, including unauthorized access to sensitive information, credential theft, and potential financial losses. The use of legitimate-looking advertisements increases the likelihood of successful infections.
How it could have been prevented
- Always verify the authenticity of websites by checking the URL and ensuring it matches the official domain.- Avoid clicking on sponsored ads for software downloads; instead, navigate directly to the official website.- Regularly update and maintain robust endpoint protection solutions to detect and prevent malware infections.
Relevant professional terms
- Infostealer
- A type of malware designed to gather sensitive information from a victim's system, such as login credentials, financial data, and personal information.
- Malvertising
- The use of online advertising to spread malware, often by embedding malicious code within legitimate-looking ads.
Recommended reading: Fake Homebrew Google ads target Mac users with malware
New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs
HighWhat happened
A previously undocumented .NET malware, dubbed CAPI Backdoor, has been identified targeting Russian automobile and e-commerce sectors. The attack involves phishing emails containing a ZIP archive, which includes a decoy document and a Windows shortcut (LNK) file that executes the malware.
Who is affected
Organizations within the Russian automobile and e-commerce industries are the primary targets of this campaign.
Why it matters
The CAPI Backdoor enables attackers to steal sensitive data from web browsers, capture screenshots, collect system information, and maintain persistent access to compromised systems, posing significant security risks to affected organizations.
How it could have been prevented
Implementing robust email filtering to detect and block phishing attempts, educating employees on recognizing phishing emails, and maintaining up-to-date antivirus software can help prevent such infections.
Relevant professional terms
- Living-off-the-land (LotL) technique
- Utilizing legitimate system tools and processes to conduct malicious activities, thereby evading detection.
- Persistence
- Methods employed by malware to maintain access to a compromised system across reboots and other interruptions.
Silver Fox Expands Winos 4.0 Attacks to Japan and Malaysia via HoldingHands RAT
HighWhat happened
The cybercrime group Silver Fox has expanded its operations, deploying the Winos 4.0 malware and HoldingHands RAT to target organizations in Japan and Malaysia through phishing emails containing malicious PDFs.
Who is affected
Organizations in Japan and Malaysia are the primary targets of these attacks.
Why it matters
The expansion of Silver Fox's activities to new regions indicates a growing threat landscape, emphasizing the need for heightened vigilance against sophisticated phishing campaigns and malware deployments.
How it could have been prevented
Implementing comprehensive email filtering to detect and block phishing attempts, and conducting regular employee training on recognizing and reporting suspicious emails.
Relevant professional terms
- Phishing
- A cyber attack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information.
- Remote Access Trojan (RAT)
- A type of malware that allows unauthorized remote control over an infected computer.
Recommended reading: HiddenGh0st, Winos and kkRAT Exploit SEO, GitHub Pages in Chinese Malware Attacks